CVE-2026-39727: WordPress WC Fields Factory plugin <= 4.1.12 - Cross Site Scripting (XSS) vulnerability
Published Oct 6, 2026
·Updated
Subscriber Cross Site Scripting (XSS) in WC Fields Factory <= 4.1.12 versions.
Affected Software
1 affected component
WordPress WC Fields Factory<=4.1.12
Event History
Oct 6, 2026
CVE Published
via MITRE·08:34 AM
Data Sourced
via MITRE·08:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is described as subscriber XSS, so an attacker needs a WordPress subscriber-level account. Exploitation also requires user interaction, as indicated by the UI:R vector.
2
What impact can successful exploitation have?
The supplied CVSS vector indicates low confidentiality, integrity, and availability impact, with scope changed. A successful attack could affect a security authority beyond the vulnerable plugin's original scope.
3
Which plugin versions are affected?
WC Fields Factory versions 4.1.12 and earlier are identified as affected.
4
Is remote exploitation possible?
Yes. The AV:N vector indicates the vulnerability can be reached over the network, but the attacker must have low-level privileges and require user interaction.